Malware

Strictor.263542 (file analysis)

Malware Removal

The Strictor.263542 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.263542 virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Strictor.263542?


File Info:

name: F509EF95EFB40380D0AE.mlw
path: /opt/CAPEv2/storage/binaries/9602f2125f8f0cda93446a9971b47070d1cb01956f29d91dd3fe2a8173e62c50
crc32: 476BF133
md5: f509ef95efb40380d0ae69f252891721
sha1: b171ee29e1182cd69722dc13c02ef6f8ed9b44e2
sha256: 9602f2125f8f0cda93446a9971b47070d1cb01956f29d91dd3fe2a8173e62c50
sha512: b9fac9314efb0f8891b3fdf34913a1e24d98b8165d1b8934aa419e1f71ec5441943fa6e77935088b3f6231e6e84ea6cdb243db1d8e60852fb6b8a5981b1904b4
ssdeep: 196608:r/zGHSkEkgf11sH5cWQb8ydznMwOImUPDxqQ/l1kugywZJre9B:r/zGHNEkgf11sH5cWQb8yKwOyDxqQ/lf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115767CBBFB85C95AF1434635070AAB77B8241E34798E5483E7D09E1E36F42E1A61CB07
sha3_384: 862f2788a4f503e4422e5cbfe21a835f74f127a98e2c77fcbdeef184b8ff5b0fbed57a427461d9c959652fe7f7557be9
ep_bytes: eb1066623a432b2b484f4f4b90e9acf0
timestamp: 2021-10-14 21:17:54

Version Info:

0: [No Data]

Strictor.263542 also known as:

LionicAdware.Win32.VKDJ.2!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGen:Variant.Strictor.263542
McAfeeGenericRXAA-AA!F509EF95EFB4
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaAdWare:Win32/Generic.44a46e6d
K7GWRiskware ( 00584baa1 )
SymantecML.Attribute.HighConfidence
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.VKDJ.pef
BitDefenderGen:Variant.Strictor.263542
MicroWorld-eScanGen:Variant.Strictor.263542
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Variant.Strictor.263542
SophosVKontakteDJ (PUA)
ZillyaAdware.VKDJ.Win32.4732
TrendMicroTROJ_GEN.R002C0WL921
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftGen:Variant.Strictor.263542 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Strictor.263542
JiangminAdWare.VKDJ.dpz
AviraHEUR/AGEN.1145843
Antiy-AVLTrojan/Generic.ASMalwS.34BD944
MicrosoftTrojan:Win32/Wacatac.A!ml
AhnLab-V3Adware/Win.Generic.R446575
VBA32Adware.VKDJ
MAXmalware (ai score=85)
MalwarebytesPUP.Optional.VkontakteDJ
TrendMicro-HouseCallTROJ_GEN.R002C0WL921
YandexPUA.VKDJ!34sG/rAm41M
FortinetRiskware/Strictor
AVGWin32:Adware-gen [Adw]
MaxSecureTrojan.Malware.300983.susgen

How to remove Strictor.263542?

Strictor.263542 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment